Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-28764

 

Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-28764

Published: November 11, 2022


Vulnerability identifier: #VU69235
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-28764
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Zoom Video Communications, Inc.
Affected software:
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for Linux
Zoom Workplace Desktop App for macOS
Zoom Workplace App for iOS
Zoom Workplace App for Android

Detailed vulnerability description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the application does not clear data from the local SQL database after a meeting ends and also uses an insufficiently secure per-device key to encrypt meetings data. A local user can obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.


How to mitigate CVE-2022-28764

Install updates from vendor's website.

Sources